Press ReleaseThreat Detection & Defense

Kaspersky ICS CERT: The Beginning of 2026 Showed Southeast Asia Reached the Highest Number of Cyberattacks on the Manufacturing Sector

Southeast Asia Ranks First Among Regions in Terms of the Percentage of ICS Computers Attacked in the Manufacturing Industry (23.21%), Followed by Africa (21.36%) and South Asia (20.13%).

According to a new Kaspersky ICS CERT report, in Q1 2026, the percentage of industrial control systems (ICS) on which malicious objects were blocked reached 19.6% globally. Kaspersky security solutions blocked malware from 10,052 different malware families of various categories on industrial automation systems. Regionally, the share of ICS computers that were attacked ranged from 27.4% in Africa to 9.1% in Northern Europe. Compared to the previous quarter, attacks on the manufacturing sector in Q1 increased in multiple regions, including Europe and Asia.

Regional Split

In terms of overall numbers across all industry sectors, five regions saw an increase in the share of attacked ICS computers in Q1 2026 compared to the previous quarter. These were Southern Europe, Russia, Northern Europe, Canada, and Africa.

Changes in the Percentage of ICS Computers on Which Malicious Objects Were Blocked,
Q1 2026 Compared to Q4 2025

In Southern Europe, the percentage of ICS computers on which malicious objects were blocked has been increasing for more than two consecutive quarters. Although Northern Europe placed last in terms of the share of ICS devices attacked, as usual, in Q1 2026 it experienced an increase in the number of targeted machines for the first time in a long period.

Manufacturing Industry

In the manufacturing industry, Southeast Asia ranks first among regions in terms of the percentage of ICS computers attacked (23.21%), followed by Africa (21.36%) and South Asia (20.13%).

In Western and Northern Europe, East Asia, Central Asia, and the South Caucasus, attacks on ICS devices in the manufacturing industry were significantly above the regional averages. Apart from that, compared to the previous quarter, attacks on manufacturing increased in Western, Eastern, Southern, and Northern Europe, South, East, and Central Asia, and Australia and New Zealand.

In 2025, Kaspersky and VDC Research estimated that, in just the first three quarters of 2025, cyberattacks on manufacturing organisations via ransomware could have generated over $18 billion globally in losses. Actual business losses could have been even higher when factoring in supply-chain disruptions, reputational damage, and recovery expenses.

The Percentage of ICS Computers on Which Malicious Objects Were Blocked in Q1 2026

Biometric Systems

The Percentage of ICS Computers on Which Malicious Objects Were Blocked in Q1 2026

In Q1, biometric systems traditionally placed first in terms of the share of ICS computers on which malicious objects were blocked, at 26.4%. These systems commonly have internet access, are used for email, and, in many cases, have minimal cybersecurity controls within the organisations that use them. Regionally, Southern Europe leads the ranking based on the percentage figures for biometric systems, at 35.15%. Africa follows at 29.58%, and Central Asia comes in third at 28.53%.

β€œLegacy operational technology systems remain deeply embedded in manufacturing environments, which makes them vulnerable. Supply chain complexity and the branching of trusted partner networks expand the attack surface beyond the network perimeter. Attackers are realising that targeting OT assets of an industrial enterprise is not rocket science, which is why factory shutdowns bring massive financial losses,” commented Evgeny Goncharov, Head of Kaspersky ICS CERT.

β€œThe fact that Southeast Asia now leads the world in cyberattacks targeting the manufacturing sector is a stark wake-up call. As our regional factories rapidly digitalise, they become prime targets for cybercriminals. ICS is the backbone of our economy, and a single breach can cause massive operational disruptions and catastrophic financial losses. Industries must move beyond basic IT security and urgently adopt specialised, robust defences for their operational technology environments,” commented Simon Tung, General Manager for ASEAN and Asia Emerging Countries (AEC) at Kaspersky.

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *